CVE-2026-92754

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.
Configurations

No configuration.

History

17 Sep 2026, 14:17

Type Values Removed Values Added
References () https://github.com/Patrowl/PatrowlManager/issues/473 - () https://github.com/Patrowl/PatrowlManager/issues/473 -

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 14:17


NVD link : CVE-2026-92754

Mitre link : CVE-2026-92754

CVE.ORG link : CVE-2026-92754


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization